DEBIAN-CVE-2026-5318

Source
https://security-tracker.debian.org/tracker/CVE-2026-5318
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5318.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-5318
Upstream
  • CVE-2026-5318
Published
2026-04-02T03:16:07.080Z
Modified
2026-04-02T15:00:11.469064Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.22.1 will fix this issue. Patch name: a6734e867b19d75367c05f872ac26322464e3995. It is advisable to upgrade the affected component.

References

Affected packages

Debian:11 / libraw

Package

Name
libraw
Purl
pkg:deb/debian/libraw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.20.2-1
0.20.2-1+deb11u1
0.20.2-1+deb11u2
0.20.2-2
0.20.2-2.1
0.21.1-1
0.21.1-2
0.21.1-3
0.21.1-4
0.21.1-5
0.21.1-6
0.21.1-7
0.21.2-1
0.21.2-2
0.21.2-2.1~exp1
0.21.2-2.1
0.21.3-1
0.21.4-1
0.21.4-2
0.21.4-3~exp1
0.21.4-3~exp2
0.21.5b-1
0.22.0-1~exp1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5318.json"

Debian:12 / libraw

Package

Name
libraw
Purl
pkg:deb/debian/libraw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.20.2-2.1
0.20.2-2.1+deb12u1
0.21.1-1
0.21.1-2
0.21.1-3
0.21.1-4
0.21.1-5
0.21.1-6
0.21.1-7
0.21.2-1
0.21.2-2
0.21.2-2.1~exp1
0.21.2-2.1
0.21.3-1
0.21.4-1
0.21.4-2
0.21.4-3~exp1
0.21.4-3~exp2
0.21.5b-1
0.22.0-1~exp1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5318.json"

Debian:13 / libraw

Package

Name
libraw
Purl
pkg:deb/debian/libraw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.21.4-2
0.21.4-3~exp1
0.21.4-3~exp2
0.21.5b-1
0.22.0-1~exp1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5318.json"

Debian:14 / libraw

Package

Name
libraw
Purl
pkg:deb/debian/libraw?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.21.4-2
0.21.4-3~exp1
0.21.4-3~exp2
0.21.5b-1
0.22.0-1~exp1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-5318.json"